golang-template/internal/auth/session.go

39 lines
930 B
Go

package auth
import (
"crypto/rand"
"crypto/sha256"
"strings"
"time"
)
const sessionExpiresInSeconds = 60 * 60 * 24 // 1 day
func GenerateSecureRandomString() (string, error) {
// Human readable alphabet (a-z, 0-9 without l, o, 0, 1 to avoid confusion)
alphabet := "abcdefghijklmnpqrstuvwxyz23456789"
// Generate 24 bytes = 192 bits of entropy.
// We're only going to use 5 bits per byte so the total entropy will be 192 * 5 / 8 = 120 bits
bytes := make([]byte, 24)
_, err := rand.Read(bytes)
if err != nil {
return "", err
}
var id strings.Builder
for _, b := range bytes {
// >> 3 "removes" the right-most 3 bits of the byte
id.WriteByte(alphabet[b>>3])
}
return id.String(), nil
}
func HashSecret(secret string) []byte {
hash := sha256.Sum256([]byte(secret))
return hash[:]
}
func CheckExpiration(expirarion time.Time) bool {
return time.Since(expirarion).Seconds() >= sessionExpiresInSeconds
}